Organizations cannot reliably detect malicious or negligent insiders because rule-based…
This technology uses probabilistic programming to detect insider threats in organizations by continuously monitoring individual user behavior on computer systems and flagging statistically unusual activity. Rather than relying on fixed rules, it builds a personalized baseline for each user and calculates how much any given action deviates from that person's normal patterns. When suspicious activity is detected, the system ranks the anomalies by severity and provides an explainable audit trail showing exactly why something was flagged. This dramatically reduces false alarms — a persistent problem in insider threat detection — and helps security teams prioritize which incidents actually warrant human investigation.
What you could build
A user behavior analytics (UBA) module or standalone SaaS platform that enterprise IT security and compliance teams deploy to monitor employee activity and surface ranked, explainable insider threat alerts. Primary buyers are large enterprises, government agencies, and defense contractors with strict data protection mandates.
Who in Virginia should care
Northern Virginia's dense concentration of federal agencies, defense contractors, and cleared IT services firms (Leidos, Booz Allen, SAIC, CACI) makes this a natural fit for government-adjacent insider threat programs.
Readiness: Prototype likely
Concept — described but not yet demonstrated. Lab validated — supported by experimental results in the patent. Prototype likely — the text describes a built, working embodiment.
Readiness is inferred from the patent text, not from a lab visit.
The record
- Inventors
- Danfeng Yao, Md Salman Ahmed, Ya Xiao
- Granted
- June 9, 2026
- Status
- Granted patent
- Patent number
- 12652300
Ready to talk?
Virginia Tech Intellectual Properties handles licensing for this technology.
Prosim summaries are generated from public patent text and are not legal advice.